Number of Web Application Hacks Up
An anonymous reader writes "According to an article at Information Week, 'Web site hacks are on the rise and pose a greater threat than the broad-based network attacks...' Citing statistics from the Web Hacking Incidents Database, 'Web hacking attacks numbered 58 in 2005, up from 16 in 2004 and 9 in 2003. Another 20 attacks have been reported this year against sites including open-source repository Sourceforge.net and social network MySpace.com, putting 2006 on pace to be the worst year yet.'"
I was thinking of writing a simple script in PHP using FTP commands & chron tab to brute hack passwords. I assume it could just check against a dictionary of common passwords, and seek syntax clues from the website content.
It wouldn't be an effective "hacking tool", but it *would* be handy for spotting dumb passwords. This would be handy for me because I have a bad habit of forgetting to disable developer FTP accounts on my server.
What say you /.? Pandora's box? Good idea? Total crap?
Math is math. Regular expression is regular expression. The tools are there. The future is now.